Why this matters now
DPDP is the most-debated current law in tech governance. Tested for: the Srikrishna Committee origins, the deemed-consent doctrine, Data Protection Board, age of consent (18), Significant Data Fiduciary classification, penalties up to Rs 250 crore, cross-border data transfer regime, and the exemption for State agencies on national security grounds.
Genesis: Srikrishna Committee → 5 drafts → 2023 Act
Puttaswamy (2017) directed the Government to frame a privacy law. The Justice B.N. Srikrishna Committee (chaired by former SC Judge B.N. Srikrishna; constituted July 2017) submitted its report and draft Personal Data Protection Bill in July 2018. The Bill went through five drafts (2018, 2019, 2021 JPC, 2022 withdrawn, 2023) — finally passed Parliament in August 2023.
Key provisions
| Concept | Provision |
|---|---|
| Data Principal | The person whose data is being processed (individual citizen). |
| Data Fiduciary | Entity that determines the purpose & means of processing data. Subject to obligations. |
| Significant Data Fiduciary | Designated by Government based on volume & sensitivity; subject to additional obligations (impact assessment, audit). |
| Consent | Notice in clear language; free, specific, informed, unambiguous. Can be withdrawn. |
| Children | Under 18 cannot consent; verifiable parental consent required. |
| Data Principal rights | Right to information about processing, right to correction & erasure, right to grievance redressal, right to nominate. |
| Data Protection Board of India | Statutory body; adjudicates breaches; appellate jurisdiction to TDSAT. |
| Penalties | Up to Rs 250 crore per breach (e.g., for failing to prevent personal data breach). |
| Cross-border transfer | Permitted EXCEPT to countries notified in negative list (vs the 2022 Bill’s whitelist approach). Centre may restrict by notification. |
| State exemption | Government may exempt its own instrumentalities from any DPDP provision “in the interest of sovereignty, integrity, security of State, public order, defence, etc.” (§ 17). Controversial. |
Comparison with EU GDPR
| Aspect | EU GDPR (2018) | DPDP 2023 |
|---|---|---|
| Sensitive data | Special category (health, religion, ethnicity) | NO separate category — criticised |
| Data localisation | Generally free flow with safeguards | Free with notified negative list |
| Right to be forgotten | Explicit (Art 17) | Implicit (correction & erasure) |
| State exemption | Limited; must be proportionate | Broad (§ 17) — criticised |
| Max penalty | 4% global turnover or €20 m | Rs 250 crore |
| Age of consent | 16 (member states can lower to 13) | 18 with verifiable parental consent |
UPSC angle
Know DPDP Act 2023 — notified 11 Aug 2023; operationalises Puttaswamy 2017; Srikrishna Committee 2018 first draft, 5 drafts total (2018/2019/2021 JPC/2022 withdrawn/2023); Data Principal = individual citizen, Data Fiduciary = entity processing, Significant Data Fiduciary = high volume/sensitivity; consent must be free/specific/informed; under-18 requires verifiable parental consent; rights to info/correction/erasure/nomination; DATA PROTECTION BOARD OF INDIA statutory body (appeal to TDSAT); penalties up to Rs 250 crore; cross-border transfer permitted except notified negative list; §17 STATE EXEMPTION on sovereignty/security grounds (controversial vs GDPR).
Frequently asked questions
When was DPDP Act notified?
11 August 2023.
Who is a Data Fiduciary?
An entity that determines the purpose and means of processing personal data — subject to obligations under DPDP.
What is the maximum penalty under DPDP?
Up to Rs 250 crore per breach (e.g., for failing to take reasonable security measures).
Does DPDP have a separate sensitive-data category?
No — unlike GDPR, DPDP does not separately categorise sensitive personal data (health, religion, etc.) — a criticism of the law.